Sign in

Anže

@anze3db.pecar.me
1.3K followers 161 following 209 posts

Writing Python and surfing waves 🏄‍♂️

PostsRepliesMedia
Anže @anze3db.pecar.me · 19h
🐍 Python Lisbon Meetup is tomorrow! 🎤 Talk by @mathsppblog ⚡ Lightning talks 🍻 Socializing 📍 IST, Sala Multiusos, Torre Norte (new room, not the Pavilhão de Matemática!) 🕖 Thu, 1 Oct, 19:00 RSVP links below 👇
100
Anže @anze3db.pecar.me · 23/09/2026
PyCon Portugal continues to be my favorite PyCon. This year it was in Aveiro (a better Venice 😉) and we had a blast! I enjoyed giving my talk on lazy imports, but the best part was meeting new people and catching up with friends. Looking forward to it again next year!
120
Anže @anze3db.pecar.me · 27/08/2026
I had a bit of a heart attack this morning when we noticed that my Grok 4.6 benchmark experiment using Amazon Bedrock would cost $28,044.59 instead of ~$28.00 that I was expecting 😱
100
Anže @anze3db.pecar.me · 26/08/2026
One of the many things that I learned at DEF CON a few weeks ago is about Python Class Pollution and how a harmless snippet like the one below can cause a huge issue if an attacker controls it!
210
Anže @anze3db.pecar.me · 31/07/2026
My dog kept me in Zone 2 for 3kms. Then I had to drop him off and immediately made bad decisions. 💛
000
Anže @anze3db.pecar.me · 31/07/2026
We benchmarked 15 models for triaging vulnerabilities. * Kimi K3 came out on top but marked a true positive as a false positive ☠️ * Opus 5 refused to give a verdict on 11 vulnerabilities * Sonnet 5 and Luna outperformed Terra and Sol Full post 👇 www.fencer.dev/blog/llm-tr...
fencer.dev
Benchmarking 15 LLMs on SAST false-positive triage
We benchmarked 15 LLMs on 142 real security findings to triage SAST false positives. Kimi K3 led on accuracy, with one caveat that matters for security.
000
Anže @anze3db.pecar.me · 27/07/2026
Quite a way to start a Monday 😅
GitHub PR stats:

+86,316 of added alines
-29 removed lines
101
Anže @anze3db.pecar.me · 21/07/2026
I do think it nailed my voice though!
Voice

First person, always. Posts are “I did X and here’s what happened”, not “one can do X”. Use “we” only for genuine team work or when walking the reader through code (“Let’s look at the view”).
Address the reader directly as “you” in tutorials: “You’ll have to add the pidfile parameter.”
Warm, enthusiastic, and self-deprecating. Admit mistakes and ugly code openly: “The one-liner has a face only a mother could love”, “which may or may not have happened in the past 🙈”.
Hedge honestly, not weaselly. Say “I haven’t tested it myself, so I’m not sure it’s foolproof” or “take the results with a grain of salt” rather than vague qualifiers.
Credit people by name with links: “Shoutout to Rémy on BlueSky”, “Thank you Hynek”. Community attribution is a core habit.
Exclamation marks are welcome when the enthusiasm is real. Emoji as sentence-final emotional beats: 🎉 for wins, 😅 for sheepishness, 🤞 for hope, 💥/☠️ for breakage, 🙈 for embarrassment. A few per post, never mid-sentence decoration.
011
Anže @anze3db.pecar.me · 21/07/2026
I asked Claude to come up with writing guidelines based on my blog posts: > A few things I deliberately did not encode as guidelines: the frequent typos (characteristic of your fast publishing cadence) 88 blog post in 14 years is not fast publishing cadence 😅
000
Anže @anze3db.pecar.me · 06/07/2026
We reviewed 4,978 mypy runs in our Django app: • 4,731 green • 246 failed Of the 246 failures: • 173 false positives • 73 real issues • 39 caught only by mypy and no other check! Some noise, but it prevented real bugs from reaching production. 🎉
101
Anže @anze3db.pecar.me · 03/07/2026
Today I migrated some Go code to Python and made it 590x FASTER 😎
100
Anže @anze3db.pecar.me · 29/06/2026
After 9 meetups full of talks, lightning talks, and even lightning turtles, it's time for the Python Lisbon Meetup to take it easy. Join us at Linha d'Água on Thursday to relax and enjoy the summer in Lisbon with Python friends 🐢 www.meetup.com/python-lisb...
meetup.com
#10 – PyLM Meetup – Social Get-Together, Thu, Jul 2, 2026, 7:00 PM | Meetup
🇬🇧 After 9 meetups full of talks, lightning talks, and even lightning turtles, it's time to take it easy. Join us at Linha d'Água — the café by the lake in Parque Eduardo
011
Anže @anze3db.pecar.me · 08/06/2026
One of my servers lost DNS after every single reboot, and it was driving me crazy. ping 8.8.8.8 worked, ping google.com didn't, and the fix never stuck. Turned out to be a config from 2010. I finally debugged it properly with Claude. blog.pecar.me/the-15-year...
blog.pecar.me
The 15-Year-Old iptables Rule That Broke My DNS
One of my servers has a weird problem after every reboot: it can ping IP addresses just fine, but it can’t resolve any DNS names. $ ping 8.8.8.8 # works $ ping google.com # ping: google.com: Temporary failure in name resolution I’ve been working around this for a while now: after every reboot I’d SSH in and overwrite /etc/resolv.conf to point straight at 8.8.8.8 instead of the local 127.0.0.53 stub. That got DNS working again, but it was never a real fix. /etc/resolv.conf is regenerated on boot, so my edit vanished the next time the machine came up and I was back to fixing it by hand. This time I decided to attempt to properly debug it with Claude.
010
Anže @anze3db.pecar.me · 26/05/2026
The Claude usage page is very confusing. Since Sonnet has a separate bar I thought I'd be able to switch to it after I max out Opus, but nope. Of course this all makes sense if you actually read the tooltip/labels but who does that today anyway? 😅
200
Anže @anze3db.pecar.me · 25/05/2026
Oh, I didn’t know GitHub doesn’t have pagination in the Commits tab of a pull request. 😅
020
Anže @anze3db.pecar.me · 22/05/2026
Make sure to always reuse your botoclients. Initializing a fresh one on each task has A LOT of overhead!
000
Anže @anze3db.pecar.me · 20/05/2026
Running Claude in a loop to push our test coverage. After 24+ hours and 22,000 new lines of tests, coverage climbed from 92% to 95%. No clue if it’ll get merged, but it's a really fun experiment 👀
100
Anže @anze3db.pecar.me · 17/05/2026
Over the last week, I've been reviewing PyCon Portugal talk and workshop proposals, and I just finished reviewing them all! 😎 Some really good ones in the mix that got me really excited about the conference in September. Make sure to grab your ticket! 2026.pycon.pt
110
Anže @anze3db.pecar.me · 13/05/2026
Claude wrote up a Cloudflare-style post mortem: blog.pecar.me/fedidevs-pos...
blog.pecar.me
Fedidevs Postmortem
Today I had almost 9 hours of downtime on fedidevs.com and some of my other sites that I run on a Raspberry Pi at home. The alert came in just as I was heading to bed and I didn’t see it until I woke ...
000
Anže @anze3db.pecar.me · 13/05/2026
Fedidevs had quite an outage today. It went offline just as I went to bed and I didn't see it until I woke up this morning 🫣 Still better uptime than GitHub 😅
000
Anže @anze3db.pecar.me · 12/05/2026
Months of training runs with my dog. Went solo today and broke almost every PR I had. He’s the real coach 🐕
130
Anže @anze3db.pecar.me · 12/05/2026
The supply chain attack has now spread to PyPI: mistralai: 2.4.6 guardrails-ai: 0.10.1 Pause your dependency updates or use package cooldowns (--uploaded-prior-to flag in latest pip) Stay safe!
023
Anže @anze3db.pecar.me · 11/05/2026
🚨 There was another supply chain attack, this time affecting tanstack npm packages. Make sure you haven't installed the compromised packages either in your CI or locally. I would also hold off on updating any dependency for the next week or so until the dust settles from this.
101
Anže @anze3db.pecar.me · 11/05/2026
I told Claude to upgrade my Raspberry Pi from Debian 12 to 13 and went to enjoy my Sunday. It wasn't an easy upgrade. apt kept tripping over Debian's t64 transition, but Claude managed to unstuck it. When I came back, the box rebooted cleanly into Debian 13. 😲
210
Anže @anze3db.pecar.me · 05/05/2026
I wrote a few words about the Agents Day hachaton that I attended last week on Friday. It's always fun to have an excuse to spend a day tinkering with something new. I even managed to be one of the 5 that got to demo their project on stage! 👉 blog.pecar.me/agents-day-...
021
Anže @anze3db.pecar.me · 04/05/2026
We have another Python Lisbon Meetup coming up on Thursday 🐍 This time Yulia will be giving a talk on strong and weak references! See you on May 7 @ 19:00 at IST, Pavilhão de Matemática, room 3.10!
100
Anže @anze3db.pecar.me · 28/04/2026
Finally wrote up my notes from DjangoCon Europe 2026 in Athens 🇬🇷 I climbed the Acropolis, ate great food, hung out with amazing people, gave a lightning talk, and fixed one regression in Django main during the sprints. blog.pecar.me/djangocon-e...
blog.pecar.me
DjangoCon Europe 2026
Before the conference My partner and I arrived in Athens a few days before the conference. It was a convenient excuse to visit a European capital we hadn’t been to yet, and of course to eat as much delicious food as possible. Django Social One day before the conference I went to the django.social event organized by Jon Gould and Andrew Miller. The bar they initially picked got too crowded, so the group moved to the backup place. I came late to the first bar, found no one there, and was a bit lost until I made it to the right spot. Once I did, I felt immediately at home. I met old friends, made some new ones, and had a very fun evening. So fun, in fact, that I forgot to take any photos, so I have no social proof that I was there 😅
011
Anže @anze3db.pecar.me · 20/04/2026
With all the supply chain attacks going around, we have to be very careful about how we update our dependencies. I've written a full blog post about it, but here is the TLDR: 1. Pin to hashes, not just versions 2. Automate the updates 3. Use dependency cooldowns blog.pecar.me/how-to-safe...
blog.pecar.me
How to Safely Update Your Dependencies
With all the supply chain attacks happening lately (litellm being the most recent example) keeping dependencies up to date without risk has been on my mind. Below is everything I do to keep my personal projects secure, what we do at Fencer to keep our own codebase secure, and what we recommend to the startups we work with. Be hesitant about what you add The best way to reduce the risk of installing a compromised dependency is to avoid relying on it in the first place. Before adding a new dependency, I first make sure that implementing it ourselves would be too much work (or tokens!).
111
Anže @anze3db.pecar.me · 12/04/2026
Everyone’s favorite web framework is now also in the gelato business 🤤
060
Anže @anze3db.pecar.me · 03/04/2026
Another Python Lisbon Meetup in the books! Looking forward to the next one on May 7 👀
021
Anže @anze3db.pecar.me · 30/03/2026
I'll be giving a talk about lazy imports at the next Python Lisbon Meetup! See you there? 😀 www.meetup.com/python-lisb...
meetup.com
#07 - PyLM Meetup at Técnico 🎓🐍, Thu, Apr 2, 2026, 7:00 PM | Meetup
**Agenda:** * 25-minute talk: **Speed Up Your Startup Times with Lazy Imports** by [Anže Pečar](https://pecar.me/) * One or more lightning talks ⚡ * Socializing! **Join t
011
Anže @anze3db.pecar.me · 25/03/2026
With recent Python supply chain attacks (Trivy/LiteLLM), it’s worth mentioning uv’s `exclude-newer = "x days"` config. It forces uv to only installs packages published more than x days ago, reducing risks since problematic packages should be yanked by then. docs.astral.sh/uv/referenc...
082
Anže @anze3db.pecar.me · 23/03/2026
I wrote a post on how we tracked down slow imports in our Django app, fixed them by making imports lazy, and added a lint check to prevent regressions. Now I’m waiting for Python 3.15 to make all of this easier! 🚀 blog.pecar.me/speeding-up...
blog.pecar.me
Speeding Up Django Startup Times with Lazy Imports
At Fancer we are building the security suite for startups. Startups use a lot of SaaS tools and services which means we are building a lot of integrations. Most of these go through API calls but we also try to leverage SDKs to make our lives a little bit easier. The problem we started noticing was that loading all these 3rd party integrations has made our Django app feel very sluggish. While this was noticeable around deployments and starting scans, it hurt the most during local development. It was taking around 10s to run ./manage.py check which meant that any Django command ended up being slow. Devs felt this the most with development server restarts and when running tests.
031
Anže @anze3db.pecar.me · 15/03/2026
Can't wait for lazy imports in Python 3.15! I spent a bunch of time and tokens over the weekend inlining heavy imports so that they don't get loaded during initial start of a Django app. The `manage.py check` command is now 3.8x faster (9.45s down to 2.48s).
040
Anže @anze3db.pecar.me · 13/03/2026
I wrote a blog post about some of the options for adding type checking to your Django project! Historically, Django projects have been tough to type-check, but the future feels bright, especially if PEP 827 gets accepted! blog.pecar.me/typing-your...
blog.pecar.me
Typing your Django project in 2026
The first version of Django was released about 10 years before Python standardized its type hints syntax. Because of this it’s not surprising that getting type hints to work in your Django project is not going to be trivial. django-stubs with mypy If you want your Django codebase to be type checked then django-stubs is the go to package to use. It ships both type-stubs for most of Django’s public APIs as well as a mypy plugin that fills in the typing information for all the dynamic black magic that we love Django for. You’ll also want to include the monkeypatch from django-stubs-ext for best results.
063
Anže @anze3db.pecar.me · 05/03/2026
Like pretty much everyone with a static blog site in the last 6 months, I asked Claude to migrate it to a different static site generator. Here's a blog post about it, along with some of my general thoughts on agentic code. blog.pecar.me/agentic-adv...
blog.pecar.me
Agentic Adventures
In my last post I mentioned that software engineering is going to be more and more AI driven and since then I’ve begrudgingly accepted this new reality. The era of handcrafted code is mostly coming to an end. I say mostly because I still believe there will always be places in our future codebases that require manual intervention. Little surgical removals and additions around the parts where the LLMs get confused and start spinning their wheels without results.
010
Anže @anze3db.pecar.me · 27/02/2026
Hey all! It's almost time for the next Python Lisbon Meetup! 🐍 On Thursday, pyctrl will be talking about exceptions. We'll cover the origin of exceptions, their usage in OOP, how best to manage them, and more. It's going to be exceptional! 💎
122
Anže @anze3db.pecar.me · 03/02/2026
Hey all! Friendly reminder that it's almost time for the next Python Lisbon Meetup! 🐍 This Thursday, @setnomt.bsky.social will be giving his talk "BEEP". It should be a blast 🔊 See you on Feb 5 @ 19:00 at IST, Pavilhão de Matemática, room 3.10!
111
Anže @anze3db.pecar.me · 21/12/2025
New board!
030
Anže @anze3db.pecar.me · 14/12/2025
I wrote a blog post about this year's Advent of Code. I had a blast and I am already looking forward to 2026! * All my Python solutions were under 1s using pure Python and 100ms with a little help from mypy/scipy • The AoC community is the best ❤️ blog.pecar.me/advent-of-c...
blog.pecar.me
Advent of Code 2025 🎄
December is the time for Advent of Code, as it has been since 2015, when the first Advent of Code event was published.
030
Anže @anze3db.pecar.me · 12/12/2025
I've finished #adventofcode 2025 and this is the first year that I managed to get all solutions under 100ms ⚡ All but two are under 10ms. Not bad for the slowest popular language out there 🐍, although I did have to use numpy a few times.
020
Anže @anze3db.pecar.me · 07/12/2025
It has been 15 years since I joined GitHub 😱
000
Anže @anze3db.pecar.me · 07/12/2025
New release of adventofcode PyPI package today improves the display of alternative solutions for each day: 1. Slower solutions are no longer counted in totals 2. Slower solutions are dimmed out Why limit yourself to one #adventofcode solution per day? 😆 Happy solving! 🎄
031
Anže @anze3db.pecar.me · 04/12/2025
I compared the first 4 #adventofcode solutions on two different CPUs. * Rows with a red background are on 8x Intel(R) Core(TM) i7-10510U CPU @ 1.80GHz. * Rows with a green background are on Apple M3 Max. So if you want to be better at advent of code just get a better CPU? 😆
040
Anže @anze3db.pecar.me · 03/12/2025
I wonder how long I'll be able to keep all the days green like this #adventofcode 🟢 Today I learned that you can use None when slicing a list in Python: >>> [1,2,3][:None] [1, 2, 3] Useful to avoid the edge case where [:0] would give an empty list: >>> [1,2,3][:0] []
031
Anže @anze3db.pecar.me · 02/12/2025
Just launched version 25.4 of my adventofcode PyPI package! 🚀 25.4 adds a `adventofcode run` command that removes the ugly boilerplate that you had to have in your puzzle files until now! Before: After:
031
Anže @anze3db.pecar.me · 02/12/2025
Day 2 of #adventofcode kinda felt easier than day 1 or was it just me? I got to the solution fairly quickly but it was a bit slow. I then spent the next hour optimizing it and managed to make part 1 200x faster and part 2 500x faster 🎉
010
Anže @anze3db.pecar.me · 01/12/2025
Day 1 of #adventofcode felt a bit harder than previous day 1 puzzles. It took me way longer to figure out part 2 than I care to admit, but I'm blaming this on my sleepy brain 😅 My code took 1.1ms for both parts without any perf optimizations 🎉 Eleven more to go!
030
Anže @anze3db.pecar.me · 30/11/2025
6 hours until the first advent of code puzzle unlocks. Who's going to participate this year? 🎄
020
Anže @anze3db.pecar.me · 29/11/2025
I've just published a new version of my adventofcode PyPI package, just in time for Advent of Code that starts in 36 hours! 🎉 I've added a command line tool that helps you scaffold all the files for puzzle days because I got annoyed by copy pasting the same file each time! pypi.org/project/adv...
100